Artefacts:
- Checklist 'Security affected areas'
- Script to integrate checklist into Jira-ticket (Tamper monkey): https://openuserjs.org/scripts/aliaksei_tatarynchykepam.com/Security_Impact_Score_Calculator
- Template 'Impact analysis'
Related reports:
- Scaling AppSec team:
- Security Champions Playbook - Alexander Antukh - ZeroNights 2017 https://www.youtube.com/watch?v=UX08VUWr8ps
- SDL at Scale: Growing Security Champions - Ryan O'Boyle - AppSecUSA 2018 https://www.youtube.com/watch?v=LsEU776Xu90
- Simplification of threat modeling process, involve developers:
- Value Driven Threat Modeling - Avi Douglen - AppSecUSA 2018 https://www.youtube.com/watch?v=3Fl_7FrM_gI
- Threat Model Every Story: Practical Continuous Threat Modeling Work for Your Team - Izar Tarandach - AppSecCali 2019 https://www.youtube.com/watch?v=VbW-X0j35gw